<?php
session_start() ;
include "functions.php" ; 
db() ; 

$zalog = (int)($_GET['zalog']) ; 
$pari = (int)($_GET['pari']) ; 

if($zalog>=0 and $zalog<=36 and !empty($zalog))
{
if($pari!=0 and $pari<=300 and !empty($zalog))
{
$parii = mysql_num_rows(mysql_query('SELECT money from users where user="'.$_SESSION['user_info']['user'].'" and money>="'.$pari.'"')) ; 
if($parii==1)
{
$rand = rand(0,36) ; 
if($zalog==$rand)
{
mysql_query('update users set money="'.($pari*2).'" where user="'.$_SESSION['user_info']['user'].'"') ; 
echo "Честито ти спечелихте $".$pari*2 ; 
}
else
{
mysql_query('update users set money=money-'.$pari.' where user="'.$_SESSION['user_info']['user'].'"') ; 
echo "Падна се числото ".$rand.".<br/>Ти загуби $".$pari.'<br/><a href="javascript:window.location.reload()">Опитай пак</a>' ; 
}
}
else
{
echo "Нямаш достатъчно пари" ; 
}
}
else
{
echo "Навалидна сума" ; 
}
}
else
{
echo "Невалидно число" ; 
}
